Lenovo's Fingerprint Scanner Can Be Bypassed via a Hardcoded Password (bleepingcomputer.com)
Lenovo has issued an update to address a vulnerability in its fingerprint scanner app that it ships with ThinkPad, ThinkCentre, and ThinkStation models running Windows 8.1 or older version of Windows. From a report: Fingerprint Manager Pro is an application developed by Lenovo that allows users to log into Windows machines and online websites by scanning one of their fingerprints using the fingerprint scanner embedded in selected Lenovo products. "A vulnerability has been identified in Lenovo Fingerprint Manager Pro," said Lenovo in a security advisory published last week. "Sensitive data stored by Lenovo Fingerprint Manager Pro, including users' Windows logon credentials and fingerprint data, is encrypted using a weak algorithm, contains a hard-coded password, and is accessible to all users with local non-administrative access to the system it is installed in," the company said.
A few years ago, Mythbusters had an episode where they showed how easy it was to fool fingerprint scanners into granting access.
The place where I work prohibits this via IT Policy and disables the fingerprint scanner on all laptops
https://www.youtube.com/watch?...
When 1person suffers from a delusion,it is called insanity.When many people suffer from a delusion,it is called religion
I expect it to have security standards that meet or exceed those of Windows 98.
And that's pretty darn high, since Windows 98 is way higher than Windows 10.
I'll see your senator, and I'll raise you two judges.
Maybe not everything works as expected, but at least it isn't leaking my stuff out!
Sent as ripples into the electromagnetic field. No single photon has been harmed in the process.
When asked for comment, one Lenovo executive responded: “This is an excellent example of Lenovo’s continued commitment to improved security. At least this time we didn’t deliberately ship a rootkit.”
Is the hard-coded password "hunter2"?
#DeleteChrome
is encrypted using a weak algorithm, contains a hard-coded password, and is accessible to all users with local non-administrative access to the system it is installed in,"
So weak encryption and a backdoor. Just the kind of thing the FBI and others want.
Modded down for sensationalist title.
This is only their older fingerprint scanners.
Current models do not have this exploit.
And it's password is the same I have on my luggage!
The master key is the same as your luggage, too.
Their finger print scanners are crappy anyway, easy to fool. So a hard coded passw0rd! is more difficult to crack than cheating the fingerprint scanner.
sed -e 's/Chuck Norris/Rajnikant/g' joke > fact
Because 10 < 95 < 98.
Therefor it follows that Win 10 < Win 95 < Win 98.
I'll see your senator, and I'll raise you two judges.